Wiselending

Kamino Finance: Program Info

app.kamino.finance

Public Bounty

Submit Reports

SCOPE

$500,000

Max Payout

Max Resolution Time

30 Business Days

13th December 2023

Start Date

Documentation

docs.kamino.finance/

RULES

Focus Area

In Scope

  • Stealing or loss of funds
  • Unauthorized transaction
  • Transaction manipulation
  • Attacks on logic (behavior of the code is different from the business description)
  • Remote code execution
  • Bugs that can facilitate attacks
  • Exposure of infrastructure private keys and/ or PII
  • Determinism bugs that could lead to inconsistent states
  • Out of Scope

  • Theoretical vulnerabilities without any proof or demonstration
  • Redundant code
  • Any encrypted credentials, auth tokens, etc. checked into the repo
  • Bugs in dependencies
  • Attacks that require social engineering
  • Unique T&Cs

  • All submissions must include a POC, showing all impacts of the vulnerability
  • Duplicate submissions don't get rewarded. First submission of each bug wins
  • REWARDS

    Critical

    $50,000 - $500,000

    High

    $10,000 - $100,000

    Medium

    $5,000 - $10,000

    Low

    $500 - $2,500